REVIEW 4 cited by
Trust No AI: Prompt Injection Along The CIA Security Triad
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
The CIA security triad - Confidentiality, Integrity, and Availability - is a cornerstone of data and cybersecurity. With the emergence of large language model (LLM) applications, a new class of threat, known as prompt injection, was first identified in 2022. Since then, numerous real-world vulnerabilities and exploits have been documented in production LLM systems, including those from leading vendors like OpenAI, Microsoft, Anthropic and Google. This paper compiles real-world exploits and proof-of concept examples, based on the research conducted and publicly documented by the author, demonstrating how prompt injection undermines the CIA triad and poses ongoing risks to cybersecurity and AI systems at large.
Forward citations
Cited by 4 Pith papers
-
Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting
Attackers can pre-register resource names that LLMs predictably hallucinate, turning agentic AI assistants into unwitting consumers of malicious promptware payloads.
-
Invitation Is All You Need! Promptware Attacks Against LLM-Powered Assistants in Production Are Practical and Dangerous
Malicious calendar invites and emails can poison Gemini's context, enabling data exfiltration, app control, and physical-world actions.
-
SAIF: A Comprehensive Framework for Evaluating the Risks of Generative AI in the Public Sector
SAIF is a proposed framework that generates multimodal test prompts from a risk taxonomy, jailbreak tricks, and prompt styles to evaluate generative AI risks in the public sector.
-
Logic layer Prompt Control Injection (LPCI): A Novel Security Vulnerability Class in Agentic Systems
LPCI is presented as a new vulnerability class for agentic LLMs, but prior work already covers memory-based prompt injection and the paper's own numbers contain errors.
Discussion (0). Continue with ORCID to comment.